Spécialiste, Sécurité de l’information Lieu de travail : Toronto, Ontario, Canada
Horaire : 37.5
Secteur d’activité : Solutions technologiques
Détails de la rémunération : $91,200 - $136,800 CAD
En tant que candidat, nous vous encourageons à poser des questions sur la rémunération et à avoir une conversation franche avec votre recruteur.
Description du poste :
Building a World-Class Technology Team at TD
TD's enterprise Vulnerability Management (VM) capability is managed as part of a multi-team organizational structure known as the VM Platform, which is a centralized organizational structure accountable for the direction, implementation, and effective and continuous delivery of all activities pertaining to the enterprise VM Operating Directive (VMOD).
The VM Governance function is part of the VMOD. As a member of the Governance function, the Information Security Specialist supports the VM Platform through operational oversight over all VM Platform functions, including:
Vulnerability Exception Management & Risk Analysis
Vulnerability Thematic Problem Analysis
Vulnerability Policies, Frameworks, Standards, Procedures
Vulnerability Platform Operational Oversight
Vulnerability Platform Capability Integrations
As a central point of contact for the VM Platform, the position provides internal TD stakeholders with a dedicated, knowledgeable, and supportive resource in facilitating matters related to vulnerabilities within the TD environment.
Key Position Objectives
Mitigate the risk to TD through the assessment, control, and reporting of exceptions to the enterprise Vulnerability Management operational objectives.
Leverage data driven insights to identify and maintain a register of operational impediments to the VM Platform's operational objectives.
Contribute to the direction of the enterprise VM Platform through the development of supporting vulnerability policies, frameworks, standards, control objectives, guidelines, and operational procedures.
Support the integration of enterprise vulnerability management capabilities, including technology solutions, governance structures, and supporting processes.
Typical Daily Activities
Vulnerability & patch exception analysis
Vulnerability standards, guidelines, process development
Monthly vulnerability risk scorecards
Design, coordination, & execution of vulnerability scenarios
Thematic deep dive tracking & analysis on operational vulnerability impediments
Internal & external stakeholder engagement (advisory & guidance)
Monitoring vulnerability regulatory and industry capability changes
What can you bring to TD? Share your credentials, but your relevant experience and knowledge can be just as likely to get our attention. It helps if you have:
Strong familiarity with navigating & operating within enterprise size organizations.
Strong experience in developing and supporting IT risk governance practices.
Experience defining key security controls and control testing.
Excellent knowledge of cybersecurity industry control standards (e.g. NIST, ISO, CIS).
Demonstrated understanding of industry vulnerability management standards (e.g. NVD CVSS).
Excellent project & time management skills.
Education/Experience
7+ years' work experience in a mid-large size organization.
Cybersecurity / IT Risk related certifications (e.g. CRISC, CISSP, CISM).
#J-18808-Ljbffr